// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 6 EXPLOIT IN THE LAST 24H
ransomware

Berlin, the Rhysida Ransomware, and the Political Cost of a Delayed Disconnect

The Berlin state government confirmed data exfiltration from two senate departments between August 7 and 12, 2026. A seven-day gap bet…

Sep 05, 2026views - 957

CYBERSECZERO-DAY

StyleSmuggler: Zero-Day Magento Under Attack Since Sept. 4, No Patch Available

The StyleSmuggler vulnerability hits Magento Open Source and Adobe Commerce with unauthenticated RCE. Adobe has issued no advisory or…

Sep 05, 2026views - 1k

CYBERSECZERO-DAY

Trezor's Phantom Certification: ShipMonk Retained Customer Data for Years

Trezor disclosed on September 4, 2026 that an additional 67,000 U.S. customers were exposed in the ShipMonk logistics breach, pushing…

Sep 05, 2026views - 982

VULNEXPLOIT

Dirty Frag: The Linux Kernel Bug That Bypasses Every Container Scanner

Dirty Frag exploits three CVEs in the Linux kernel to corrupt the page cache and gain root. The problem isn't in Docker images—it's in…

Sep 05, 2026views - 1.1k

CYBERSEC

From AI to Inbox: The 'Invisible' Technique That Flooded Corporate Email

Microsoft detected a campaign sending over 2 million messages per day by embedding invisible Unicode characters inside financial keywo…

Sep 04, 2026views - 969

VULNCRITICAL

HPE Patches Two Critical RCE Flaws in ArubaOS-CX: Structural Technical Debt

HPE released patches on September 1, 2026 for 34 vulnerabilities in the ArubaOS-CX (AOS-CX) platform, the operating system powering en…

Sep 04, 2026views - 1k

CYBERSEC

"ted" Backdoor in HAProxy: Load Balancer Turned Spy in South Korea

Rapid7 Labs uncovered a previously undocumented Linux toolkit that injects the "ted" backdoor into HAProxy 2.8.12 to intercept traffic…

Sep 04, 2026views - 998

CYBERSEC

CNIL Fines French Hospital €500K: 727,000 Profiles Exposed Without MFA or VPN

France's data protection authority fined Hôpital privé de la Loire €500,000 for a 2025 breach that exposed 727,113 individuals. The at…

Sep 03, 2026views - 1.1k

CYBERSECCRITICAL

Backup Turned Weapon: How the All-in-One WP Migration Plugin Exposes 3.2 Million Sites

CVE-2026-19949: A second-order SQL injection in the WordPress plugin All-in-One WP Migration enables remote code execution via the res…

Sep 03, 2026views - 1.1k

CYBERSEC

GitHub Reveals the True Cost of Ingesting Threat Intelligence at Scale

The Dependabot lead details how ingesting 18 malicious packages per day across 30 million repositories demanded more validation engine…

Sep 03, 2026views - 1.1k

CYBERSEC

Silver Fox Pushes Fake Installers That Kill Windows Update and Weaken Defender

Microsoft exposes a campaign by the Chinese Silver Fox cluster using pixel-perfect clone sites of popular software to deliver installe…

Sep 02, 2026views - 1.2k

CYBERSEC

Dark Web: 153 Million Driver's Licenses for Sale, FBI Investigates IDScan.net

The Nexus dark web platform claims 153 million U.S. and Canadian driver's licenses. KrebsOnSecurity empirically verified records and t…

Sep 02, 2026views - 1.7k